<div><br>In both vpn servers you have the same .conf file??</div>
<div>&nbsp;</div>
<div>Or one with left configuration: left -&gt; local, reight -&gt; remote,</div>
<div>and the other: left-&gt; remote, right-&gt;local??</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>in vpn1 server, .conf file:</div>
<div>&nbsp;</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; left=private external ip</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; leftid=@private external ip</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; leftsubnet=ip_lan1<br>&nbsp;&nbsp;&nbsp; &nbsp;&nbsp; leftnexthop=ip_private r1&nbsp;&nbsp; &nbsp;&nbsp; (may not be needed in new version)<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; right=ip_public remote<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href="mailto:rightid=@ private">rightid=@ private</a> external ip of&nbsp;server 2
<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; rightsubnet=ip_lan2<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://192.168.1.0/24" target="_blank"></a><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; authby=secret<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; auto=start<br>&nbsp;</div>
<div>&nbsp;</div>
<div>in vpn2 server, .conf file:</div>
<div>&nbsp;</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; left=ip_public remote</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; leftid=@<u><font color="#0000ff">private</font></u> external ip of&nbsp;server 1</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; leftsubnet=ip_lan1<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; right=private external ip&nbsp;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href="mailto:rightid=@ private">rightid=@ private</a>&nbsp;external ip</div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; rightsubnet=ip_lan2<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://192.168.1.0/24" target="_blank"></a></div>
<div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; rightnexthop=ip_private r2<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; authby=secret<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; auto=start<br>&nbsp;</div>
<div>Am I wrong??</div>
<div>&nbsp;</div>
<div>Xavi.</div>
<div>&nbsp;</div>
<div><br>&nbsp;</div>
<div><span class="gmail_quote">2007/3/8, Utkarsh Shah &lt;<a href="mailto:utkarsh@elitecore.com">utkarsh@elitecore.com</a>&gt;:</span>
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">
<div text="#000000" bgcolor="#ffffff">left=privateip and right =public ip is correct.<br>and on your adsl router you have to make few rules like<br>anything comming on router&#39;s public ip <br>&nbsp;&nbsp;&nbsp; on UDP port 500 or port 4500 should be redirected to your vpn server&#39;s private ip which is behind your adsl router
<br>&nbsp;&nbsp;&nbsp; and proto ESP should be redirected to your vpn server&#39;s private ip which is behind your adsl router<br>this are the rules you have to apply on both adsl routers.<br><br>eg. <br>&nbsp;&nbsp;&nbsp; source=any<br>&nbsp;&nbsp;&nbsp; destination=router1&#39;s public ip
<br>&nbsp;&nbsp;&nbsp; protocol UDP<br>&nbsp;&nbsp;&nbsp; port 500/4500<br>&nbsp;&nbsp;&nbsp; forward it to vpnserver1&#39;s private ip<br>same way at other end<br><br>and i think on adsl router you might have facility to disable passthrough of vpn or ipsec<br>and can make a rule to redirect ipsec/vpn service to a desired destination 
<div><span class="e" id="q_1112fe55a340a835_1"><br><br>Regards,<br>Utkarsh Shah<br><br>Xavi Deop wrote: 
<blockquote cite="http://mid22fa9c0b0703071012id25aecame4b9b0c95f481182@mail.gmail.com" type="cite">
<div>&nbsp;</div>
<div>Is this correct??</div>
<div>&nbsp;</div>
<div>If in vpn server1 we have: left=private ip; right= public ip.</div>
<div>&nbsp;</div>
<div>Shouldnt we had in vpn server: left=public ip; right= private ip ?????</div>
<div>&nbsp;</div>
<div>Thanks.</div>
<div>&nbsp;</div>
<div>Xavi.<br><br>&nbsp;</div>
<div><span class="gmail_quote">2007/3/7, Utkarsh Shah &lt;<a onclick="return top.js.OpenExtLink(window,event,this)" href="mailto:utkarsh@elitecore.com" target="_blank">utkarsh@elitecore.com</a>&gt;:</span> 
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: rgb(204,204,204) 1px solid">
<div text="#000000" bgcolor="#ffffff">assuming &quot;ip1_1&nbsp;&nbsp;&nbsp; ip1_2&quot; is vpnserver1 and another is vpnserver2<br><br>at vpnserver1<br>conn vpnserver1-to-vpnserver2<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; left=ip1_2<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; leftid=@ip1_2<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; leftsubnet=ip_lan1 
<br>&nbsp;&nbsp;&nbsp; &nbsp;&nbsp; leftnexthop=ip_r1&nbsp;&nbsp; &nbsp;&nbsp; (may not be needed in new version)<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; right=ip_pub2<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; rightid=@ip2_2<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; rightsubnet=ip_lan2<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://192.168.1.0/24" target="_blank">
 </a><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; authby=secret<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; auto=start<br><br>at vpnserver2<br>conn vpnserver2-to-vpnserver1<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; left=ip2_2<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; leftid=@ip2_2<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; leftsubnet=ip_lan2<br>&nbsp;&nbsp;&nbsp; &nbsp;&nbsp; leftnexthop=ip_r2&nbsp;&nbsp; &nbsp;&nbsp; (may not be needed in new version) 
<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; right=ip_pub1<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; rightid=@ip1_1<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; rightsubnet=ip_lan1<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; authby=secret<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; auto=start<br><br><br>Regards,<br><span>Utkarsh Shah</span> 
<div><span><br><br>Xavi Deop wrote: 
<blockquote cite="http://mid22fa9c0b0703070144j4515a2eeg9e6465e30fb3ca22@mail.gmail.com" type="cite">
<div>Hi, thanks for your replies!!</div>
<div>&nbsp;</div>
<div>I&#39;m a bit confused with the addresses, sorry...</div>
<div>&nbsp;</div>
<div>I have 2 ethernets in my vpn servers.</div>
<div>&nbsp;</div>
<div>This configuration file sample, is for one of the vpn servers, that&#39;s right? For the otherone, there should be changes, no??</div>
<div>&nbsp;</div>
<div>if my scenario had:<br>&nbsp;</div>
<div>LAN_1 ------ vpn server --- router adsl ------ internet---- router adsl&nbsp;------- vpn server ----- LAN_2</div>
<div>ip_lan1&nbsp;&nbsp;&nbsp;&nbsp; ip1_1&nbsp;&nbsp;&nbsp; ip1_2&nbsp; ip_r1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ip_pub1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ip_pub2&nbsp;&nbsp;&nbsp; ip_r2&nbsp; ip2_2&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;ip2_1&nbsp;&nbsp; ip_lan2</div>
<div>&nbsp;</div>
<div>how would it be the configuration?</div>
<div>&nbsp;</div>
<div>what is: @leftid @rightid?? which addresses should be?</div>
<div>&nbsp;</div>
<div>Thanks in advance!</div>
<div>&nbsp;</div>
<div>Xavi.</div>
<div>&nbsp;</div>
<div><span class="gmail_quote">2007/3/7, Utkarsh Shah &lt;<a onclick="return top.js.OpenExtLink(window,event,this)" href="mailto:utkarsh@elitecore.com" target="_blank">utkarsh@elitecore.com</a>&gt;:</span> 
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: rgb(204,204,204) 1px solid"><br>&gt; Hi, I have the following scenario, and I would like to create a vpn with<br>&gt; natt suport. 
<br>&gt;<br>&gt; LAN_1 ------ vpn server --- router adsl ------ internet---- router adsl<br>&gt; ----- vpn server ----- LAN_2<br>&gt;<br>&gt; I&#39;ve installed:<br>&gt; openswan-2.4.7.tar.gz&lt;<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.openswan.org/download/openswan-2.4.7.tar.gz" target="_blank">
 http://www.openswan.org/download/openswan-2.4.7.tar.gz</a>&gt;<br>&gt;<br>&gt; I&#39;m working with slackware 10.1 and kernel 2.16.12<br>&gt;<br>&gt; I have to install the kernell natt patch??<br>&gt;<br>&gt; Could someone help me with 
ipsec.conf file? I&#39;ve been searching the internet<br>&gt; without any result...<br>&gt;<br>&gt; Thanks.<br>&gt;<br>&gt; Xavi<br>i have achieved above scenario with following changes it might not be<br>perfect solution... 
<br>on adsl router apply portforwarding rules for UDP port 500 port 4500 and<br>proto esp(50) to your vpn server on both end<br><br>configure your ipsec.conf as below<br><br>conn net-to-net<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; left=<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.0.1.2/" target="_blank">
 10.0.1.2</a><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; leftid=@leftid<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; leftsubnet=<a onclick="return top.js.OpenExtLink(window,event,this)" href="http://192.168.0.0/24" target="_blank">192.168.0.0/24</a><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; right=remoteserver(domain name or ip which will identify adsl router) 
<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; rightid=@rightid<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; rightsubnet= <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://192.168.1.0/24" target="_blank">192.168.1.0/24</a><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; authby=secret<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; auto=start<br>
<br>and your ipsec.secret as<br><br>@leftid @rightid : PSK &quot;your preshared key&quot;<br><br><br><br>Regards,<br>Utkarsh Shah <br>_______________________________________________<br><a onclick="return top.js.OpenExtLink(window,event,this)" href="mailto:Users@openswan.org" target="_blank">
Users@openswan.org</a><br><a onclick="return top.js.OpenExtLink(window,event,this)" href="http://lists.openswan.org/mailman/listinfo/users" target="_blank">http://lists.openswan.org/mailman/listinfo/users </a><br>Building and Integrating Virtual Private Networks with Openswan: 
<br><a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155" target="_blank">http://www.amazon.com/gp/product/1904811256/104-3099591-2946327?n=283155 
</a><br></blockquote></div><br></blockquote><br></span></div></div></blockquote></div><br></blockquote><br></span></div></div></blockquote></div><br>